Database/Control plane, storage & DevOps
AmdCpmDisplayFeatureSMM - SMM callout (AMD-SB-7027): An SMM callout in the AmdCpmDisplayFeatureSMM driver lets ring-0
Impact
An SMM callout in the AmdCpmDisplayFeatureSMM driver lets ring-0 code overwrite SMRAM. SMM callouts are the classic UEFI escalation pattern: SMM code calls outward into memory the OS controls, so the OS supplies the code SMM then runs. Reported by Quarkslab, scored 8.2 with changed scope - the attacker crosses from the OS into the platform's most privileged context.
Who can reach it
Local, ring-0 on the host.
What to do
Fixed in AMD PI/AGESA firmware and delivered only as an OEM SBIOS package - AMD ships the PI drop to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before releasing BIOS. **Budget one to six months of OEM lag**, and note that several CVEs in this batch are marked 'no fix planned' on Naples (EPYC 7001) - for those the only remediation is retiring the hardware. Applying it means cordon, drain and a full power cycle per node; there is no driver reload, no live patch and no VBIOS step. Patch alongside the sibling AmdPspP2CmboxV2 issue in the same bulletin - they ship together and leaving one open leaves the class open.
References
Related entries
- Moxa NPort W2150A / W2250A wireless device server: A remote attacker can crash or potentially gain code executionCVE-2024-1220 · Moxa NPort W2150A / W2250A wireless device serverHigh
- AmdPlatformRasSspSmm - SMM callout (AMD-SB-7028): An SMM callout in the platform RAS SMM driver lets ring-0 code modifyCVE-2024-21924 · AmdPlatformRasSspSmm - SMM callout (AMD-SB-7028)High
- AmdPspP2CmboxV2 - SMM input validation (AMD-SB-7027): Insufficient input validation in the AmdPspP2CmboxV2 SMM driverCVE-2024-21925 · AmdPspP2CmboxV2 - SMM input validation (AMD-SB-7027)High
- OpenTelemetry Collector: Unsafe decompressionCVE-2024-36129 · OpenTelemetry CollectorHigh
- VMware Aria Automation (DOM-based XSS, token theft): A crafted URL steals the access token of a logged-in AriaCVE-2025-22249 · VMware Aria Automation (DOM-based XSS, token theft)High
- OpenShift Hive / MCE / ACM (vCenter credential exposure): vCenter credentials are written into the ClusterProvisionCVE-2025-2241 · OpenShift Hive / MCE / ACM (vCenter credential exposure)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.